EP4222620A1 - Verfahren zur steuerung des zugriffs auf dienste, zugehörige verfahren und zugehörige vorrichtungen - Google Patents

Verfahren zur steuerung des zugriffs auf dienste, zugehörige verfahren und zugehörige vorrichtungen

Info

Publication number
EP4222620A1
EP4222620A1 EP21798073.9A EP21798073A EP4222620A1 EP 4222620 A1 EP4222620 A1 EP 4222620A1 EP 21798073 A EP21798073 A EP 21798073A EP 4222620 A1 EP4222620 A1 EP 4222620A1
Authority
EP
European Patent Office
Prior art keywords
communication terminal
service
authentication
identifier
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP21798073.9A
Other languages
English (en)
French (fr)
Inventor
Patrick KIRSCHBAUM
Sylvie GASPAR
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
Orange SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Orange SA filed Critical Orange SA
Publication of EP4222620A1 publication Critical patent/EP4222620A1/de
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • G06F21/35User authentication involving the use of external additional devices, e.g. dongles or smart cards communicating wirelessly
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/42User authentication using separate channels for security data
    • G06F21/43User authentication using separate channels for security data wireless channels
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/629Protecting access to data via a platform, e.g. using keys or access control rules to features or functions of an application
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2149Restricted operating environment

Definitions

  • TITLE Process for controlling access to services, associated processes and associated devices
  • the invention relates to the personalization and control of access to remote services.
  • the purpose of the invention is to allow personalization of television services while allowing control of the owner of the customer account liable to the access provider for bills for the consumption of services such as videos, pay television or video games, etc.
  • the subject of the present invention is a method for controlling access to services, the services being provided by a device for providing services intended for a reproduction system, characterized in that the method comprises the following steps implemented by the service provision mechanism:
  • this control method allows high control of the use of his account by the holder of the account with an access provider.
  • many services can be controlled such as accessible channels, favorite channels and by extension all the services available by a service provider such as the control of connected objects, home automation services or even alarms.
  • this control can be carried out remotely with a high level of security and does not require the physical presence of the account holder in front of the television.
  • the request for access to said at least one service received was sent by a device among the following:
  • a reproduction system comprising a communication network communication unit and a display screen.
  • the customer account includes at least one service identification linked to the identifier of the first communication terminal and to the identifier of the customer account, said access being given to the communication terminal identified only for the service or services (s) having a service identification mentioned in the customer account and linked to the identifier of the first communication terminal.
  • the customer account comprises an identifier of a second communication terminal having subscribed to the customer account and an authentication code of said second communication terminal, and in which the customer account comprises an authorization on request, the method further comprising the following steps:
  • the services are provided by a service provision device, said service provision device being connected to a communication network, said service provision device hosting a database storing at least one customer account, the customer account being identified by an identifier, the customer account comprising identification data linked to the identifier of the customer account, the identification data comprising an identifier of at least one first communication terminal and at least one code of authentication of said at least one first communication terminal; said first communication terminal having a right to use the customer account, said first communication terminal comprising at least one communication network communication unit, an access control application, and an authentication application capable of generating the authentication code.
  • the invention also relates to a service provision device providing services intended for a reproduction system, the service provision device comprising:
  • a confirmation request transmitter to a first communication terminal associated with a customer account in the service provision device, following receipt of a request for access to at least one service, the access request coming from the reproduction system and comprising an identifier of said customer account,
  • this process makes it possible to increase the knowledge of the customer by the service provider. It also allows for finer management of customer preferences.
  • the invention also relates to a method for confirming with a device for providing services a request for access to at least one service, characterized in that the method comprises the following steps implemented by the first terminal Communication :
  • an authentication code being generated by an authentication application after authentication of biometric data of the owner of the first communication terminal or after authentication of a personal identification number entered on the first communication terminal.
  • this method is easy and quick to use for the first communication terminal.
  • said authentication code of the first communication terminal is generated only after authentication of biometric data of the owner of the first communication terminal.
  • the invention also relates to a communication terminal characterized in that it further comprises an access control application suitable for receiving a confirmation request and for transmitting an authentication code generated by an authentication application after authentication of biometric data of the owner of the first communication terminal or after authentication of a personal identification number entered on the first communication terminal.
  • the invention also relates to a method for enriching a memory of a service providing device to control access to services, said service providing device being connected to a communication network, said provision of services comprising a generator suitable for generating an installation code, characterized in that the method comprises the following steps implemented by the service provision device:
  • the customer account can be easily and quickly enriched by registering a new first terminal.
  • it is also easy and quick to delete a first communication terminal existing in the database.
  • the method further comprises the following steps:
  • the method further comprises a step of transmitting a text message to the first communication terminal to confirm the recording of said at least one service identification in the memory of the service provision device.
  • the invention also relates to a method for installing on a first communication terminal a service access control, characterized in that the method comprises the following steps implemented by the first communication terminal connected to the communications network:
  • the access control application can be easily installed.
  • said authentication code of the first communication terminal is generated only after authentication of biometric data of the owner of the first communication terminal.
  • FIG. 1 is a schematic view of an example of a service access control system, the system comprising a service provision device and a user communication terminal according to the invention
  • FIG. 2 is a table representing an example of data stored in two customer accounts of a database of the service provision device according to the invention
  • FIG. 3 is a chronogram representing the main steps of a process for enriching a database and a process for installing access control on a first communication terminal;
  • FIG. 4 is a timing diagram representing the main steps of the access control method according to the invention implemented by the service provision device and representing the main steps of the method for confirming a request for access to a service by a first communication terminal; and
  • FIG. 5 is a chronogram representing the main steps for implementing the authorization on request function.
  • a communication terminal belonging to a user who has subscribed to the services offered by a service provision device is called a “second communication terminal”.
  • Another communication terminal belonging to a user distinct from the user having subscribed to the subscription is called “first communication terminal”.
  • the first communication terminal benefits from access to the services by means of a usage authorization given by the user of the second communication terminal.
  • the methods according to the invention are implemented in an access control system 1 such as the system represented in FIG. Referring to Figure 1, the access control system 1 comprises a communication network 12, a second communication terminal 2 connected to the network 12, a first communication terminal 6 connected to the network 12 and possibly one or more reproduction 28 also connected to the network 12.
  • the communication network 12 is for example an Internet network.
  • the exchanges comply with the Internet protocol.
  • the communication terminals 2.6 are, for example, mobile telephones of the smart type (“Smartphone”). They comprise a communication unit 16 to the network 12, a display screen 22, a SIM card, USIM, or a microSIM card. They can be connected to the communication network 12 via a wireless access network, such as a GSM, UMTS, 3G, 4G, 5G mobile network, etc.
  • a wireless access network such as a GSM, UMTS, 3G, 4G, 5G mobile network, etc.
  • the communication terminals 2, 4 include in memory an authentication application 18 adapted to implement the steps of an authentication method based on the recognition of a personal identification number (also called pin code) or on the basis of the recognition of a biometric element such as the fingerprint.
  • the communication terminals 2, 4 are equipped with a fingerprint sensor, a retinal analysis module, and/or a facial recognition module.
  • the authentication application is configured to check that this biometric data is indeed identical to that of the holder of the communication terminal.
  • the authentication application When this biometric data is identical to that of the holder of the communication terminal, the authentication application generates an authentication code AUTC2, AUTU6.
  • This authentication code is specific to each communication terminal.
  • the acceptance of the biometric data is used to authenticate the communication terminal.
  • the biometric data itself is not used and is not stored in the memory of the communication terminal.
  • each reproduction system 28 comprises a communication unit 16 to the communication network and a display screen 22.
  • the reproduction system 28 can for example be constituted by either a reproduction terminal such as a personal computer 30, a tablet or a television directly connected to the communication network, or by an assembly 32 comprising a television 32 connected by wired or wireless link to the TV decoder.
  • the reproduction system can be used by different users.
  • the reproduction terminal is distinct from the first communication terminal 6.
  • the access control system 1 further comprises a service provision device 10 connected to the network 12.
  • the service provision device is a web server which hosts paid online services. These services include the supply of multimedia content such as, for example, pay television, video games, films, music, videos (replay, VOD), home automation services. Services are web services. They can be obtained by means of a browser executed on the communication terminals or on a reproduction system.
  • the service provision device comprises web pages making it possible to receive requests and to transmit information to communication terminals of the mobile telephone type or to reproduction systems 28 so as to provide the service in question.
  • the service provision device 10 comprises or is linked to a memory storing a database 14.
  • the database is stored in the service provider server.
  • the embodiment shown in Figure 1 is in no way limiting.
  • the database 14 stores customer accounts C2, C4.
  • Figure 2 shows an example of two customer accounts C2, C4.
  • the customer account C2 subscribed by the second communication terminal 2 is identified by an identifier referenced “ID2-Account”.
  • the customer account C4 subscribed by the second communication terminal 4 is identified by a different identifier referenced “ID4-Account”.
  • Each customer account includes identification data linked to the customer account identifier.
  • the identification data contained in the customer account C2 include: an identifier IDC2 of the second communication terminal 2, an authentication code AUTC2 of the second communication terminal, an installation code CD2, and for each first communication terminal having a right to use the customer account C2,
  • an identifier of the first communication terminal - for example the identifiers IDU6, IDU8 of the first communication terminals 6, 8,
  • an authentication code of the first communication terminal - for example the authentication codes AUTU6, AUTU8 of the first communication terminals 6, 8
  • service identifications C1, C4, V authorized for the first communication terminal for example service identifications C1, C4, V for the first communication terminal 6 and service identifications C5, C7, JV authorized for the first communication terminal 8, and possibly an authorization on request SD.
  • All of the identification data is linked to the identifier of the customer account, for example to the identifier "ID2-Account" in the example described above.
  • the right of use is the possibility offered to a customer holding a customer account to share the services acquired through the subscription to his customer account with users of communication terminals.
  • a list of the identifiers of the first communication terminals having this right of use is transmitted by the holder of the customer account to the service provider server.
  • Patent application FR 2008839 in the name of the applicant describes an example of the implementation of such a right of use.
  • the identifier of the second communication terminal 2 is, for example, the telephone number of the second communication terminal 2.
  • the identifier of the first communication terminal 6 is, for example, the telephone number of the first communication terminal 6.
  • the identifier of the second communication terminal and the identifier of the first communication terminal can be their international mobile subscriber identity number IMSI.
  • the authentication codes AUTC2, AUTU6 are generated by the authentication applications 18 after authentication of biometric data of the owner of the second communication terminal or of the first communication terminal.
  • the authentication codes can also be generated after authentication of a personal identification number entered on the second communication terminal or on the first communication terminal.
  • the CD2 installation code is a temporary code generated by a code generator 24. It is specific to each customer account. It is only used when installing access control on a first communication terminal and when enriching the database 14 by adding one or more new first terminals communication as explained later in connection with the method illustrated in Figure 3.
  • the service identifications C1, C4, V consist of codes enabling the services to be identified.
  • the codes C1 , C4 represent television channels 1 and 4.
  • the codes V and JV represent a video service and a video game service respectively.
  • the code M represents a music service.
  • Authorization on request SD is a function allowing the holder of the customer account to give occasional and non-permanent authorizations for use.
  • the account holder receives a service access authorization request message each time a first communication terminal 6 or a reproduction system 28 transmits a service request to the service provider server. services.
  • the customer account holder can then authorize or refuse the service. This refusal or acceptance is only valid for this access authorization request.
  • the first communication terminal 6 or the reproduction system 28 will have to redo an access authorization request when it again wishes to have access to this service.
  • the second communication terminal can accept or refuse this new request regardless of the choice (acceptance or refusal) it made during the first access authorization request.
  • Authorization on request SD is a function that is implemented only on the services mentioned for a first communication terminal given in the customer account. These services will have been previously mentioned by the second communication terminal. The method for implementing the authorization on request SD will be described later in connection with FIG. 5.
  • the service provision device 10 also comprises at least one generator 24 of an installation code capable of generating temporary codes specific to each customer account. These temporary codes comprise for example four digits.
  • each customer account includes an installation code generator 24.
  • the service provision device comprises a single generator capable of generating installation codes for all of the customer accounts.
  • the access control system 1 comprises a server 26 connected to the network 12.
  • This server 26 comprises an access control application 20 which can be distributed under the management of mobile terminals, also called MDM application (from the English “Mobile Device Management”).
  • This access control application 20 is capable of being downloaded onto first communication terminals or onto second communication terminals.
  • the access control application 20 to be downloaded is stored on the service provision device 10.
  • FIG. 3 illustrates the steps of a method for enriching the memory of the device 10 and in particular of the database 14 and of a method for installing a service access control on the first communication terminal 6.
  • At least one customer account 2 has already been created and that it already comprises the following identification data: an identifier IDC2 of the second communication terminal, an authentication code AUTC2 of the second communication terminal, an identifier IDU6, IDU8 of the first communication terminals having a right to use the customer account, and a authentication code AUTU6, AUTU8 of the first communication terminals having a right to use the customer account.
  • FIG. 3 illustrates an example of implementation of the method for enriching the database 14 in which the holder of the customer account C2 subscribed by the owner of the second communication terminal 2 requests access control to the services provided to the first communication terminal 6 and the first communication terminal 8.
  • the process for enriching the database 14 begins with a step 68 during which the service provision device 10 receives a message containing the identifier ID2-Account of the customer account, the identifier IDU6, IDU8 of the first communication terminals 6,8 and service identifications associated with the first communication terminal 6 and the first communication terminal 8. Only the services having the identifications contained in the message are authorized to be viewed by the first communication terminal which is assigned to them. associated.
  • the message includes, for example, the service identifications C1, C2 and V associated with the first communication terminal 6 and the service identifications C5, C7 and JV associated with the first communication terminal 8.
  • the service identifications C1, C2 and V correspond to channel 1 , channel 2 and video content.
  • the service identifications C5, C7 and JV correspond to channel 5, channel 7 and video games.
  • the message may also comprise an “authorization on request” function SD linked to a service identification and to an identification of the first communication terminal.
  • Step 68 of transmitting the identifier of the customer account, the identifier of the first communication terminal, service identifications and possibly the SD “authorization on request” function can be implemented:
  • the transmission of the authentication code AUTC2 of the second communication terminal can only be carried out from the second communication terminal 2
  • the service provision device records, during a step 72, the service identifications C1, C2, V in the database 14 so that they are linked to the identifier "ID2-Account” of the customer account C2 and to the identifier IDU6 of the first communication terminal.
  • the service identifications C5, C7 and JV are recorded in the database 14 so that they are linked to the "ID2-Account” identifier of the customer account C2 and to the identifier IDU8 of the first communication terminal.
  • the "authorization on request" function SD is recorded in connection with the identifier of the customer account "ID2-Account", with the identifier IDU6 of the first communication terminal and with the service identification associated.
  • the “authorization on request” function has been requested by the second communication terminal 2 for the video service V for the first communication terminal 6 identified by the identifier IDU6.
  • the authorization function on request SD has been requested by the second communication terminal 2 for the video game service JV for the first communication terminal 8 identified by the identifier IDU8.
  • the service identifications C1, C4 and V and the associated authorization function SD on request constitutes the “profile” of the first communication terminal identified by the identifier IDU6.
  • the service identifications C5, C7 and JV and the associated authorization function SD on request constitutes the “profile” of the first communication terminal 8 identified by the identifier IDU8.
  • the generator 24 generates an installation code CD2.
  • the service provision device records the installation code CD2 in the customer account C2 so that this code is linked or coupled to the identifier of the customer account “ID2-Account”.
  • the service provision device 10 transmits a short message to the first communication terminal 6 and a short message to the first communication terminal 8.
  • These short messages include the installation code CD2.
  • the installation code CD2 To simplify Figure 3, only the first communication terminal 6 has been shown therein.
  • the first communication terminal 6 receives the short message transmitted by the service provision device.
  • the first communication terminal 6 downloads an access control application 20 from a server 26.
  • the user of the first communication terminal 6 saves the CD2 installation code received by text message in the access control application 20.
  • the user of the first communication terminal 6 captures biometric data such as capturing a fingerprint.
  • the authentication application 18 verifies that this biometric data is indeed identical to that of the holder of the first communication terminal.
  • the authentication application 18 generates an authentication code AUTU6.
  • the user of the first communication terminal 6 enters a personal identification number in the authentication application 18 which generates an authentication code AUTU6 if this personal identification number is recognized.
  • the first communication terminal 6 transmits a message to the service provision device 10. This message includes the installation code CD2, the authentication code AUTU6 generated during step 84 and the identifier IDU6 of the first communication terminal 6.
  • the service provision device 10 receives the message comprising the installation code CD2, the authentication code AUTU6 of the first communication terminal and the identifier IDU6 of the first communication terminal.
  • the service provision device saves the received authentication code AUTU6 in the database 14 so that the latter is linked to the identifier of the customer account and to the identifier IDU6 of the first communication terminal.
  • the service provision device uses the installation code CD2.
  • the service provision device transmits a short message to the first communication terminal 6 to confirm the registration in the database 14.
  • Steps 79 to 90 are also implemented with the first communication terminal 8.
  • the authentication code AUTU6 of the first communication terminal is generated only after authentication of biometric data of the owner of the first communication terminal 6.
  • this variant is more secure because it makes it possible to guarantee that it is indeed the owner of the first communication terminal who makes the authentication request.
  • the method for installing a service access control on the first communication terminal 6 comprises the steps 79, 80, 82, 84 and 85 mentioned above.
  • the service access control method can be implemented by the service provision device 10.
  • the method begins when a user connects to a customer account from a reproduction system 28.
  • This reproduction system 28 is for example a set 32 comprising a television connected to a TV decoder or "set top box" in English . Profiles appear on the TV screen. The user selects his profile using his remote control.
  • the service provision device 10 then receives during a step 52, a service request from the reproduction system 28.
  • the service request comprises the identifier IDC2 of the customer account and the identifier IDU6 of the first communication terminal 6 linked to the profile selected by the user.
  • the service provision device transmits a confirmation by text message to the first communication terminal 6.
  • the first communication terminal 6 receives the short message. Then, the user of the first communication terminal 6 makes a capture of biometric data such as capture of a fingerprint. The authentication application 18 verifies that this biometric datum is indeed identical to that of the holder of the communication terminal. When this biometric data is identical to that of the holder of the communication terminal, the authentication application 18 generates an authentication code AUTU6. As a variant, the user of the first communication terminal 6 enters a personal identification number in the authentication application 18 which generates an authentication code AUTU6 if this personal identification number is recognized. During a step 56, the first communication terminal 6 transmits an authentication code AUTU6 to the service provision device 10. During a step 57, the service provision device 10 receives the authentication code AUTU6 from the first communication terminal 6.
  • the service provision device 10 compares the authentication code AUTU6 received with the authentication code AUTU6 recorded in its database 14 and linked to the identifier of the first communication terminal 6.
  • the service provision device 10 authorizes, during a step 60 , access to the services identified in the profile of the first communication terminal.
  • the method of confirming with a service provision device 10 a request for access to a viewing service comprises the steps 55 and 56 mentioned above.
  • the method further comprises a step 62 during which the service provider device transmits an authorization request on request SD , by short message, to the second communication terminal 2.
  • the owner of the second communication terminal 2 enters a response from among acceptance or refusal and captures biometric data or enters a pin code. If this biometric data or this pin code is recognized, the authentication application 18 generates an authentication code AUTC2. Then, the first communication terminal transmits to the service provision device the response and the authentication code AUTC2 of the second communication terminal. communications 2.
  • the service provider device receives the response and the authentication code AUTC2 from the second communication terminal. Then, the service provider device 10 implements the response during a step 60, if the received authentication code AUTC2 is identical to the authentication code AUTC2 of the second communication terminal stored in the customer account.
  • a user can have his communication terminal identifier registered with several customer account holders as represented in FIG. 2.
  • the user of the communication terminal identified by the identifier IDU6 is registered with the same service provider. These television profiles are different from one customer account to another. These accesses to the services provided by the service provision device are managed by the same access control application 20.
  • the first communication terminal of a home childcare provider could only access channels for children chosen by the parent holding the customer account. Thus, the home child care provider would not be able to watch programs that are inappropriate for the child.
  • the first communication terminal When the identifier of the first communication terminal is registered with two different service providers, the first communication terminal must download onto its first communication terminal two different access control applications each specific to a service provider.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Biomedical Technology (AREA)
  • Telephonic Communication Services (AREA)
EP21798073.9A 2020-09-30 2021-09-24 Verfahren zur steuerung des zugriffs auf dienste, zugehörige verfahren und zugehörige vorrichtungen Pending EP4222620A1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR2009999A FR3114666A1 (fr) 2020-09-30 2020-09-30 Procédé de contrôle d’accès à des services, procédés associés et dispositifs associés
PCT/FR2021/051654 WO2022069823A1 (fr) 2020-09-30 2021-09-24 Procede de controle d'acces a des services, procedes associes et dispositifs associes

Publications (1)

Publication Number Publication Date
EP4222620A1 true EP4222620A1 (de) 2023-08-09

Family

ID=76730575

Family Applications (1)

Application Number Title Priority Date Filing Date
EP21798073.9A Pending EP4222620A1 (de) 2020-09-30 2021-09-24 Verfahren zur steuerung des zugriffs auf dienste, zugehörige verfahren und zugehörige vorrichtungen

Country Status (5)

Country Link
US (1) US20230396627A1 (de)
EP (1) EP4222620A1 (de)
CN (1) CN116685970A (de)
FR (1) FR3114666A1 (de)
WO (1) WO2022069823A1 (de)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12309152B2 (en) * 2023-08-15 2025-05-20 Citibank, N.A. Access control for requests to services

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CH465456A (de) 1968-05-20 1968-11-15 Rieter Ag Maschf Zwirnmaschine
CN103369391B (zh) 2007-11-21 2016-12-28 高通股份有限公司 基于媒体偏好控制电子设备的方法和系统
US8442498B2 (en) * 2008-12-19 2013-05-14 Verizon Patent And Licensing Inc. Methods, systems and computer program products for remote DVR interface provisioning
US9537661B2 (en) * 2014-02-28 2017-01-03 Verizon Patent And Licensing Inc. Password-less authentication service
US20170085563A1 (en) * 2015-09-18 2017-03-23 First Data Corporation System for validating a biometric input
US10110608B2 (en) * 2016-01-07 2018-10-23 Google Llc Authorizing transaction on a shared device using a personal device

Also Published As

Publication number Publication date
CN116685970A (zh) 2023-09-01
FR3114666A1 (fr) 2022-04-01
US20230396627A1 (en) 2023-12-07
WO2022069823A1 (fr) 2022-04-07

Similar Documents

Publication Publication Date Title
BE1009081A4 (fr) Methode et systeme de distribution de signaux a des abonnes en regle.
US8255981B2 (en) System and method of authentication
WO2008049792A2 (fr) Méthode de chargement et de gestion d'une application dans un équipement mobile
FR2985130A1 (fr) Procede de partage d'un contenu multimedia entre au moins un premier utilisateur et un second utilisateur sur un reseau de telecommunications
EP1454489A1 (de) Protokoll zur steuerung des zugriffsmodus von im punkt-zu-punkt- oder im punkt-zu-mehrpunkt-modus übertragenen daten
EP2795870B1 (de) Verfahren zur ermöglichung des zugriffs eines telekommunikationsendgeräts auf eine von einer über ein telekommunikationsnetz zugängliche dienstplattform gehostete datenbank
EP1867190B1 (de) Verwaltung des zugangs zu multimedia-inhalten
EP4222620A1 (de) Verfahren zur steuerung des zugriffs auf dienste, zugehörige verfahren und zugehörige vorrichtungen
FR3117295A1 (fr) Procédé de gestion d’une demande d’accès à un réseau de communication local, procédé de traitement d’une demande d’accès à un réseau de communication local, procédé de demande d’accès à un réseau de communication local, dispositifs, plateforme de gestion, passerelle, terminal utilisateur, système et programmes d’ordinateur correspondants.
EP1552694B1 (de) Datenentschlüsselungssystem für bedingten zugang
EP1983722A2 (de) Verfahren und System zur Internetzugangssicherung bei Mobiltelefonen sowie entsprechendes Mobiltelefon und Endgerät
FR2946212A1 (fr) Dispositif et procede d'interfacage d'au moins un terminal de stockage et de tranmission de donnees avec au moins un support de transmission de donnees
WO2003071760A1 (fr) Dispositif et procede d'intermediation entre fournisseurs de services et leur utilisateurs
FR2955450A1 (fr) Procede d'authentification d'un terminal mobile pour acceder a un serveur d'applications
FR3113801A1 (fr) Procédé de fourniture à un terminal de communication tiers d’une autorisation d’usage d’un compte client, procédés associés et dispositifs associés
EP3235255B1 (de) Vorrichtung und verfahren zur prioritätsverwaltung zum herunterladen von multimedia inhalten
EP1326399B1 (de) Verfahren zur Sicherung des Herunterladens von aktiven Daten auf ein Kommunikationsgerät
EP3228083B1 (de) Verfahren zur verwaltung des zugriffsrechts auf einen digitalen inhalt
EP2907316A1 (de) Profilmanagement für digitales fernsehen
WO2021044102A1 (fr) Procédé pour activer des droits d'accès à un service auquel a souscrit un abonné
FR3136921A1 (fr) Gestion de l’authentification d’un terminal pour accéder à un service d’un fournisseur de service.
FR2972882A1 (fr) Procede de transfert et de comptabilisation de tags, et dispositif correspondant
FR2811504A1 (fr) Dispositif serveur de realisation multi-utilisateur en libre-service et de diffusion d'emissions de television et reseau de television
FR2863440A1 (fr) Procede et dispositif de filtrage de flux multimedia.
FR2913168A1 (fr) Procede,dispositif et systeme multimedia maille, reconfigurable et adapte aux latentes evolutions des besoins de services et de performances

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20230403

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
RAP3 Party data changed (applicant data changed or rights of an application transferred)

Owner name: ORANGE